A malformed proposed entry of the intoto/v0.0.2 type can cause a panic on a thread within the Rekor process. The thread is recovered so the client receives a 500 error message and service still continues, so the availability impact of this is minimal.
This is fixed in v1.2.0 of Rekor.
No
Discovered by OSS-Fuzz
{
"github_reviewed_at": "2023-05-26T19:39:03Z",
"severity": "MODERATE",
"github_reviewed": true,
"nvd_published_at": "2023-05-26T23:15:18Z",
"cwe_ids": [
"CWE-617"
]
}